Mumbai Police: 2,805 malicious APKs, 9,673 victims, ₹150 crore — developer as a service for cyber gangs
Mumbai Crime Branch has arrested a 36-year-old Madhya Pradesh software developer accused of building and selling 2,805 malicious Android APKs to fraud gangs. Police link the apps to 9,673 victims nationwide and about ₹150 crore in fraud. The case shows how ready-made malware is sold as a service outside Google Play.
MUMBAI: Mumbai Crime Branch has arrested a 36-year-old software developer from Madhya Pradesh accused of building and selling 2,805 malicious Android APKs to cyber fraud gangs across India.
According to Mumbai Police, the apps are linked to fraud against 9,673 victims nationwide, with estimated losses of about ₹150 crore.
Analysis of helpline 1930 complaints has so far tied the apps to 1,074 cases, including 143 in Maharashtra and 36 in Mumbai, with 88 FIRs registered.
The investigation began after a 72-year-old Byculla resident lost ₹5.62 lakh after installing a “Senior Citizen Card Verification” APK sent on WhatsApp.
Police named the accused as Pankaj Avhdesh Gupta, 36, of Indore, a BTech dropout who rented server space and sold the apps as a technical service to gangs that contacted him for custom malware.
The numbers
- 2,805 malicious APKs developed and sold
- 9,673 victims identified so far
- About ₹150 crore in estimated fraud linked to the apps
- 1,074 complaints on helpline 1930; 143 in Maharashtra; 36 in Mumbai
- 88 FIRs registered across India
- Seized from his Madhya Pradesh office: 1 CPU, 3 hard disks, 1 pen drive, 1 Wi-Fi router, 3 phones
Modus operandi
Fraudsters called or messaged victims, posing as bank or government staff, and offered pension card verification, life certificates, senior citizen cards, traffic challan clearance or credit card updates.
Victims were told to install an APK sent by WhatsApp or link, outside the Play Store.
Once installed, the app harvested personal and debit card details used to empty accounts.
Gupta allegedly acted as the supplier: he marketed himself as an APK developer after a first contact from a fraudster, then sold packs of malicious apps to gangs nationwide.
What Google is doing
These APKs bypass the Play Store through internet sideloading from browsers, messaging apps and file managers.
Google Play Protect already scans apps on devices; in India it has rolled out enhanced fraud protection that automatically blocks sideloaded installs declaring permissions fraudsters abuse most (SMS read/receive, notification access and Accessibility).
Google says Play Protect scans about 200 billion apps a day and that real-time scanning has flagged more than 10 million new malicious apps globally.
Official advice remains: install only from the Play Store, keep Play Protect on, and never grant Accessibility or SMS permissions to an unknown APK.